Demystifying Limited Adversarial Transferability in Automatic Speech Recognition Systems

Demystifying Limited Adversarial Transferability in Automatic Speech Recognition Systems
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
H. Abdullah;Aditya Karlekar;Vincent Bindschaedler;Patrick Traynor
H. Abdullah;Aditya Karlekar;Vincent Bindschaedler;Patrick Traynor
中科院分区:
其他
文献类型:
--
作者:
H. Abdullah;Aditya Karlekar;Vincent Bindschaedler;Patrick Traynor

文献摘要

被引文献

相似文献

对抗样本的有针对性的可转移性使攻击者能够利用现实世界中的黑盒模型。优化攻击是生成此类可转移样本的最流行方法。这是因为这些样本在某些领域具有高水平的可移植性。然而,最近的研究表明,这些攻击的样本在应用于自动语音识别系统 (ASR) 时不会传输。在本文中,我们研究了这一现象,进行了详尽的实验,并确定了阻碍 ASR 可迁移性的因素。为此,我们对 ASR 管道的每个阶段进行消融研究。我们发现并量化了影响 ASR 优化攻击的目标可转移性的六个因素(即输入类型、MFCC、RNN、输出类型以及词汇和序列大小)。我们的研究结果可用于设计对其他可转移攻击类型(例如信号处理攻击)更稳健的 ASR,或者修改其他领域的架构以减少其对目标可转移性的脆弱性。
The targeted transferability of adversarial samples enables attackers to exploit black-box models in the real world. Optimization attacks are the most popular means of producing such transferable samples. This is because these samples have high levels of transferability in some domains. However, recent research has shown that samples from these attacks do not transfer when applied to Automatic Speech Recognition systems (ASRs). In this paper, we study this phenomenon, perform exhaustive experiments, and identify the factors that are preventing transferability in ASRs. To do so, we perform an ablation study on each stage of the ASR pipeline. We discover and quantify six factors (i.e., input type, MFCC, RNN, output type, and vocabulary and sequence sizes) that impact the targeted transferability of optimization attacks against ASRs. Our findings can be leveraged to design ASRs that are more robust to other transferable attack types (e.g., signal processing attacks), or to modify architectures in other domains to reduce their vulnerability to targeted transferability.